CRITICAL 9.0 npm
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
GHSA-p293-qw3h-jr36 · CVE-2026-75604
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.
Workaround
There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.
References
- WEB https://github.com/vercel/next.js/security/advisories/GHSA-p293-qw3h-jr36
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-75604
- WEB https://github.com/vercel/next.js/commit/968b9fcb26bdeb8e0a861a9df05361474666d51b
- WEB https://github.com/vercel/next.js/commit/b0f3460a92b955d3ca41fccff9a525a2b910fbf3
- PACKAGE https://github.com/vercel/next.js
- WEB https://github.com/vercel/next.js/releases/tag/v15.5.24
- WEB https://github.com/vercel/next.js/releases/tag/v16.3.3
Ready to move
Start Securing
Free, no credit card | First findings in minutes